Weekly WP Vulnerabilities: 6/16/25 – 6/22/25

via Wordfence Email

Last week, there were 131 vulnerabilities disclosed in 124 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 44 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Table of Contents

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-849 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-853 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Patched40
Unpatched91

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Medium Severity121
High Severity8
Critical Severity2

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)59
Missing Authorization29
Cross-Site Request Forgery (CSRF)25
Unrestricted Upload of File with Dangerous Type5
Server-Side Request Forgery (SSRF)4
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)3
Incorrect Authorization2
Authorization Bypass Through User-Controlled Key1
Deserialization of Untrusted Data1
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Fitness Parkfitness-park
Hello FSE Bloghello-fse-blog
HYDRO – One Page Portfolio WordPress Themehydro
OceanWPoceanwp
Spark Multipurposespark-multipurpose

WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Galleryinteractive-3d-flipbook-powered-physics-engine
AI Engineai-engine
Anant Addons for Elementoranant-addons-for-elementor
ANON::form embedded secure formanonform-embedded-secure-form
App Builder – Create Native Android & iOS Apps On The Flightapp-builder
ATP Call Nowatp-call-now
Auto Upload Imagesauto-upload-images
Automatically Hierarchic Categories in Menuautomatically-hierarchic-categories-in-menu
Beaver Builder Plugin (Starter Version)bb-plugin
Better Random Redirectbetter-random-redirect
Blog2Social: Social Media Auto Post & Schedulerblog2social
Bluff Postbluff-post
Breeze – WordPress Cache Pluginbreeze
Bulk YouTube Post Creatorbulk-youtube-post-creator
Buying Buddy IDX CRM – Real Estate MLS Pluginbuying-buddy-idx-crm
Change Cart button Colors WooCommercewc-style
ClipLinkcliplink
Code Enginecode-engine
CodePen Embed Blockcodepen-embed-block
Contact Form 7 AWeber Extensionintegrate-contact-form-7-and-aweber
ContentStudiocontentstudio
Cookie-Script.comcookie-script-com
Creative Contact Formsexy-contact-form
CRM ERP Business Solution | freelancers & SME | for WordPress & WooCommercecrm-erp-business-solution
CSV Importer Improvedcsv-importer-improved
CSV Mecsv-me
Download Managerdownload-manager
Drag and Drop Multiple File Upload for Contact Form 7drag-and-drop-multiple-file-upload-contact-form-7
eDS Responsive Menueds-responsive-menu
Elementor Website Builder Proelementor-pro
Elementor Website Builder – More Than Just a Page Builderelementor
ElementsKit Elementor Addons and Templateselementskit-lite
Enhanced Blocks – Page Builder Blocks for Gutenbergenhanced-blocks
Esselink.nu Settingsesselinknu-settings
Euro FxRef Currency Convertereuro-fxref-currency-converter
FastBook – Responsive Appointment Booking and Scheduling Systemfastbook-responsive-appointment-booking-and-scheduling-system
File Manager Pro – Filesterfilester
Firelight Lightboxeasy-fancybox
Football Poolfootball-pool
FormLift for Infusionsoft Web Formsformlift
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommercewp-marketing-automations
Fyrebox Quizzesfyrebox-shortcode
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followersrafflepress
GiveWP – Donation Plugin and Fundraising Platformgive
Guest posting / Frontend Posting / Front Editor – WP Front User Submitfront-editor
Gutenberg Blocks – ACF Blocks Suiteacf-blocks
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addonsgutenverse-news
Hand Talkhandtalk
HUSKY – Products Filter Professional for WooCommercewoocommerce-products-filter
Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizesimage-sizes-controller
Import YouTube videos as WP Postsimport-youtube-videos-as-wp-post
Inventory Presser – Car Dealer Listingsinventory-presser
IP Based Loginip-based-login
Job Postingsjob-postings
JobSearch WP Job Boardwp-jobsearch
JobWP – Job Board, Job Listing, Career Page and Recruitment Pluginjobwp
Kata Plus – Addons for Elementor – Widgets, Extensions and Templateskata-plus
Knowledge Base – Knowledge Base Makerknowledge-base-maker
Lewe ChordPress – ChordPro Text Formatterchordpress
Live Sports Streamthunderlive-sports-streamthunder
Login & Register Customizer – Popup | Slider | Inline | WooCommerceeasy-login-woocommerce
Logo Manager For Samandehisamandehi-logo-manager
Mailing Group Listservwp-mailing-group
Master Slider – Responsive Touch Slidermaster-slider
Media Hygiene: Remove or Delete Unused Images and More!media-hygiene
Modern Footnotesmodern-footnotes
Oganro Travel Portal Search Widget for HotelBeds APITUDE APIoganro-travel-portal-search-widget-for-hotelbeds-apitude-api
PDPA Consent for Thailandpdpa-consent
Pixabay Imagespixabay-images
Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and morewoocommerce-google-adwords-conversion-tracking-tag
PixelBeds Channel Manager and Hotel Booking Enginepixelbeds-channel-manager-booking-engine
Poll, Survey & Quiz Maker Plugin by Opinion Stagesocial-polls-by-opinionstage
Polls CPcp-polls
Post and Page Builder by BoldGrid – Visual Drag and Drop Editorpost-and-page-builder
PowerPress Podcasting plugin by Blubrrypowerpress
RDFa Breadcrumbrdfa-breadcrumb
Real Estate Manager – Property Listing and Agent Managementreal-estate-manager
Recipes manager – WPHwph-recipes-manager
Related Products Manager for WooCommercerelated-products-manager-woocommerce
School Management System for WordPressschool-management
Scroll UPscroll-to-up
Send Notifications from Woocommerce, Form Plugins and More!notifier
Simple Logo Carouselsimple-logo-carousel
Simple Sticky Footersimple-sticky-footer
Sitekitsitekit
Smart Notification WordPress Plugin. Web & Mobile Push, FB Messenger, FB Notifications & Newsletter.smio-push-notification
SpecFit-Virtual Try On Woocommercetry-on-for-woocommerce
Spoki – Chat Buttons and WooCommerce Notificationsspoki
TableOn – WordPress Posts Table Filterable posts-table-filterable
Target Video Easy Publishbrid-video-easy-publish
Tealiumtealium
TinyNavtinynav
TM Replace Howdytm-replace-howdy
Ultra Addons for Contact Form 7ultimate-addons-for-contact-form-7
UpStream: a Project Management Plugin for WordPressupstream
User Roles and Capabilitiesuser-roles-and-capabilities
Video List Managervideo-list-manager
Virtual Moderatorvirtual-moderator
Wise Chatwise-chat
WooCommerce Fortnox Integrationwoocommerce-fortnox-integration
Woocommerce Line Notifywoo-line-notify
WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easilyinnovs-woo-manager
WordPress Infinite Scroll – Ajax Load Moreajax-load-more
WP Customer Areacustomer-area
WP Dummy Content Generatorwp-dummy-content-generator
WP Inventory Managerwp-inventory-manager
WP Register Profile With Shortcodewp-register-profile-with-shortcode
WP Roadmap – Product Feedback Boardwp-roadmap
WP Social AutoConnectwp-fb-autoconnect
WP User Profile Avatarwp-user-profile-avatar
WP User Stylesheet Switcherwp-user-stylesheet-switcher
WP Visitor Statistics (Real Time Traffic)wp-stats-manager
WP Voting Contest Litewp-voting-contest
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigincf7-zoho
WP-DownloadCounterwp-downloadcounter
WP-Members Membership Pluginwp-members
WP-Recall – Registration, Profile, Commerce & Morewp-recall
WPBakery Page Builder for WordPressjs_composer
WPCompletewpcomplete
WPThumbwp-thumb
XML Travel Portal Widgetoganro-reservation-widget
YITH PayPal Express Checkout for WooCommerceyith-paypal-express-checkout-for-woocommerce
Zapier for WordPresszapier
Zara 4 Image Compressionzara-4

Have ServiceNow & WordPress? Purchase ServicePress Core and get ServicePress: Wordfence Security (add-on) for Free.

Wordfence Plugin

Leave a Reply

Your email address will not be published. Required fields are marked *